Bandcampro Gemini CLI botnet operation
Malware Activity
Summary
Hide ▲
Show ▼
The bandcampro botnet operation used Google's open-source Gemini CLI to run and migrate C2 infrastructure, letting the actor manage infected systems and generate attack tasks. The activity spanned more than 200 sessions and included control of eight systems in a dental clinic, raising the risk of follow-on access and credential abuse. The operator also used the tool for password guessing and analysis of 1Password dumps, expanding the possible attack surface.
Related Happenings
Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime
Threat Actor Meta
H score36
First: 20.07.2026 12:07
Last: 20.07.2026 12:07
Sources 1
About this happening:
Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-as...
Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime
Threat Actor MetaAbout this happening: Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-as...
Dental clinic hit by network compromise
Incident
H score12
First: 20.07.2026 12:07
Last: 20.07.2026 12:07
Sources 1
About this happening:
A dental clinic suffered an unauthorized compromise after a threat actor used Google Gemini CLI to run C&C infrastructure that controlled eight computers and r...
Dental clinic hit by network compromise
IncidentAbout this happening: A dental clinic suffered an unauthorized compromise after a threat actor used Google Gemini CLI to run C&C infrastructure that controlled eight computers and r...
GoBruteforcer botnet brute-forces exposed Linux servers with a more capable mid-2025 variant
Malware Activity
H score72
First: 08.01.2026 19:30
Last: 08.01.2026 19:30
Sources 1
About this happening:
GoBruteforcer is actively brute-forcing Linux servers exposed to the internet, creating a broad risk of compromise, data theft and botnet expansion. The operation...
GoBruteforcer botnet brute-forces exposed Linux servers with a more capable mid-2025 variant
Malware ActivityAbout this happening: GoBruteforcer is actively brute-forcing Linux servers exposed to the internet, creating a broad risk of compromise, data theft and botnet expansion. The operation...
Timeline
-
15.07.2026 21:33 2 articles · 13d ago
bandcampro used Gemini CLI to run and migrate a small botnet
Initial DisclosureA Russian-speaking threat actor known as bandcampro used Google's open-source Gemini CLI as a hacking agent to operate a small-scale botnet, migrate its C2 infrastructure, and manage eight systems in a dental clinic while seeking access to the OpenDental database. The AI handled architecture, coding, VPS deployment, Cloudflare configuration, initial debugging, and reconnect troubleshooting, while the operator also used it for password guessing and analysis of 1Password dumps.
Show sources
- Google Gemini CLI abused as a hacking agent, malware botnet operator — www.bleepingcomputer.com — 15.07.2026 21:33
- Google Gemini CLI abused as a hacking agent, malware botnet operator — www.bleepingcomputer.com — 15.07.2026 21:33